Skip to content

Repository files navigation

Trivy Operator Explorer

This project explores the reports generated by the Trivy Operator for Kubernetes across one or more clusters. It is split into two applications that share this repository:

  • collector (cmd/collector): runs inside each cluster, reads the trivy-operator custom resources (plus running-pod/container data), and writes a copy of them to an S3 bucket namespaced by cluster name. The bucket is multi-tenant, so many clusters can write into it.
  • frontend (cmd/frontend): reads the report bundles from S3 for every cluster and serves the web UI, JSON API, and MCP server. It supports selecting a single cluster or viewing an aggregated "All clusters" mode.

Architecture

                per-cluster                       central
  ┌───────────────────────────┐        ┌──────────────────────────┐
  │ trivy-operator CRs + Pods  │        │ frontend (web / API / MCP)│
  │            │               │        │            ▲             │
  │            ▼               │        │            │ read        │
  │        collector ──────────┼──put──►│         S3 bucket        │
  └───────────────────────────┘        │  <prefix>/<cluster>/*.json│
                                        │  sqlite: ignored CVEs     │
                                        └──────────────────────────┘

S3 layout

Each collector writes one JSON object per report type under its cluster prefix:

<prefix>/<cluster>/vulnerabilityreports.json
<prefix>/<cluster>/clustercompliancereports.json
<prefix>/<cluster>/rbacassessmentreports.json
<prefix>/<cluster>/clusterrbacassessmentreports.json
<prefix>/<cluster>/configauditreports.json
<prefix>/<cluster>/clusterinfraassessmentreports.json
<prefix>/<cluster>/exposedsecretreports.json
<prefix>/<cluster>/containerimages.json
<prefix>/<cluster>/meta.json

The frontend discovers clusters by listing the common prefixes under <prefix>/.

AWS credentials for both apps are resolved via the standard AWS SDK credential chain (environment variables, shared config, and in-cluster IRSA / web-identity).

Install

Pre-requisites

You will need Trivy Operator installed in each cluster you want to scan, plus an S3 bucket that the collectors can write to and the frontend can read from.

Install the collector (per cluster)

helm upgrade --install --create-namespace \
--repo "https://starttoaster.github.io/trivy-operator-explorer" \
-n trivy-explorer \
--set config.clusterName=my-cluster \
--set s3.bucket=my-trivy-reports \
--set s3.region=us-east-1 \
trivy-operator-collector \
trivy-operator-collector

Install the frontend (once, centrally)

helm upgrade --install --create-namespace \
--repo "https://starttoaster.github.io/trivy-operator-explorer" \
-n trivy-explorer \
--set s3.bucket=my-trivy-reports \
--set s3.region=us-east-1 \
trivy-operator-explorer \
trivy-operator-explorer

Using an S3-compatible store (MinIO, Garage, ...)

Both apps can talk to any S3-compatible object store, not just AWS. Two optional settings control this; both default to the current AWS behavior, so existing installs are unaffected.

Chart value Flag Environment variable Default
s3.endpoint --s3-endpoint TRIVY_OPERATOR_{COLLECTOR,EXPLORER}_S3_ENDPOINT empty (AWS endpoints)
s3.usePathStyle --s3-use-path-style TRIVY_OPERATOR_{COLLECTOR,EXPLORER}_S3_USE_PATH_STYLE false
  • s3.endpoint must be a full http:// or https:// URL; the apps refuse to start on anything else (e.g. a bare host:port). If it is empty, the AWS SDK's own resolution applies, including the AWS_ENDPOINT_URL_S3 environment variable.
  • s3.usePathStyle addresses the bucket as <endpoint>/<bucket>/<key> instead of <bucket>.<endpoint>/<key>. Most self-hosted stores need this unless wildcard DNS is set up for bucket hostnames. The AWS SDK has no environment variable or config-file setting for it, which is why it is an explicit option here.
  • Set s3.region to whatever region your store expects (Garage's default is garage); the request signature must match it.
  • Credentials still come from the standard AWS credential chain. Static keys can be provided via extraEnv (e.g. AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY from a Secret).

Example (Garage in the same cluster), for both the collector and the frontend:

--set s3.bucket=trivy-reports \
--set s3.region=garage \
--set s3.endpoint=http://garage.garage.svc.cluster.local:3900 \
--set s3.usePathStyle=true

Some S3-compatible stores reject the AWS SDK's default request checksums. If yours does, you can optionally set AWS_REQUEST_CHECKSUM_CALCULATION=when_required and AWS_RESPONSE_CHECKSUM_VALIDATION=when_required through extraEnv. This is not needed for stores that accept them (Garage v2.4 accepts the defaults).

Pre-release / unstable charts

Stable charts are published from main to https://starttoaster.github.io/trivy-operator-explorer. While the two-app rework is baking on a release/** branch, release-candidate charts are published to a separate unstable channel on every push to that branch:

helm repo add trivy-operator-explorer-unstable \
  https://starttoaster.github.io/trivy-operator-explorer/unstable
helm repo update

# See the available pre-release versions (they look like 0.1.0-unstable.42).
helm search repo trivy-operator-explorer-unstable --devel --versions

Install a specific candidate with --devel (so Helm considers pre-release versions) and an explicit --version. Each unstable chart pins appVersion to the sha-<commit> image built from the same commit, so the chart and image always match.

Multi-cluster UI

The sidebar has a cluster selector. Choosing a cluster scopes every page to that cluster via a ?cluster=<name> query parameter; "All clusters" aggregates all of them and shows a Cluster column. The same cluster parameter is accepted by the JSON API and as an optional argument to the MCP tools.

JSON API

A JSON API mirroring every HTML page is exposed under /api/v1/..., along with CVE-ignore management and a machine-readable OpenAPI 3 spec at /api/v1/openapi.json. See docs/API.md for the full route list and examples.

TODO

See CONTRIBUTING.md if you'd like to contribute an item on this list. Please make an Issue if you would like to see something added to this list.

  • SBOM dashboard

About

A web explorer for the Trivy Operator for kubernetes.

Topics

Resources

Contributing

Stars

5 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages